
The White House recently introduced a framework for classifying frontier AI models by capability. At the same time, companies like Microsoft are building AI platforms that automatically route work across multiple models depending on the task being performed. The AI inside a single application is becoming more dynamic, more specialized and more difficult to track.
That increases the governance challenge for every local government.
Many organizations have approved vendors like Microsoft, Google or OpenAI for employee use. That approval provided reasonable oversight when AI was primarily a chatbot or writing assistant. Today, those same vendors offer multiple language models, specialized reasoning models, image generation, coding assistants and autonomous agents. Those capabilities continue to expand through regular product updates.
A vendor name no longer tells you enough about how AI is operating inside your organization.
I've spent the last year helping organizations think through AI readiness, and one observation keeps surfacing. Most AI governance discussions focus on employee behavior. They establish policies for acceptable use, privacy, public records and human oversight. Those are all necessary. They describe how people should use AI.
Far fewer organizations maintain a current understanding of the AI systems performing the work.
That distinction becomes more important every month.
Consider a city that licenses Microsoft 365. Over time, Microsoft introduces new Copilot capabilities. Some features summarize meetings. Others analyze spreadsheets. Some can take actions across connected systems. The underlying models improve. New agent capabilities become available. Employees begin using features that did not exist when the software was originally approved.
The city's AI footprint expands without a corresponding increase in visibility.
The same pattern is playing out across permitting software, finance systems, GIS platforms, public safety applications and customer service tools. AI is increasingly arriving through software the organization has already owned for years.
Governance cannot depend on someone noticing a product announcement.
I believe every city will eventually need an AI operating system.
An AI operating system is not another chatbot. It is the layer that helps leaders understand, govern and continuously monitor AI across the organization.
It knows which AI capabilities exist, where they are being used, who is responsible for them and how they have changed over time. It alerts leaders when vendors introduce significant new capabilities. It evaluates new models before they are widely deployed. It documents which departments are using AI and where additional oversight may be appropriate.
Just as importantly, it creates a common operating picture for executives, IT leaders, attorneys, records managers and department directors.
Florida has already taken important steps toward practical AI governance. The Florida League of Cities AI Hub provides guidance on privacy, records retention, procurement, workflow automation and responsible implementation. Those resources help cities make better decisions as they adopt AI.
The next challenge is operational.
How does a city maintain visibility into an AI environment that changes every week?
That requires more than a policy document.
At the Artificial Intelligence Center of Excellence, we're exploring what that next layer of governance could look like as part of a broader vision for civic AI infrastructure. An AI operating system would give local governments a practical way to understand the technologies already operating across their organizations while creating the foundation for future capabilities such as Civic Language Models and other components of a modern Civic Stack.
Cities have spent decades building systems to manage their finances, assets, records and public services. AI has become another operational system that deserves the same level of discipline.
The organizations that develop that visibility first will be better prepared to adopt AI responsibly because they'll understand exactly what they're governing.
A Practical Model for Building an AI Operating System
Start with visibility. Create an inventory of every application and service that contains AI capabilities, including software that has added AI since it was originally purchased.
Monitor continuously. Track model updates, new agent capabilities and significant vendor changes instead of relying on annual policy reviews.
Assign ownership. Give every AI capability a responsible department and accountable owner who reviews its purpose, risks and ongoing performance.
Build for the future. Design governance as a living operational system that can support transparency, local AI initiatives and emerging technologies as they are introduced.
